漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Frappe account takeover via password reset token leakage
Vulnerability Description
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances configured in a certain way. Frappe Cloud users are safe. This issue has been patched in versions 14.94.3 and 15.58.0. Workarounds for this issue involve verifying password reset URLs before clicking on them or upgrading for self hosted users.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Frappe Technologies Frappe 信息泄露漏洞
Vulnerability Description
Frappe Technologies Frappe是印度Frappe Technologies公司的一个基于Python、Mariadb的并集成前端页面的Web开发框架。 Frappe Technologies Frappe 14.94.3之前版本和15.58.0之前版本存在信息泄露漏洞,该漏洞源于特制请求可能导致密码重置令牌泄露。
CVSS Information
N/A
Vulnerability Type
N/A